XRAY: unknown licenses Troubleshooting
Following our Knowledge Base where Artifacts/Licenses may be manually marked as vulnerable, in this article you will find information regarding the Impacted Path (available from Xray version 3.44.1) of the identified unknown license.
In some cases, Xray will identify Unknown Licenses and we will want to understand where the licenses came from in the Artifact. For this case, we can use the Impact Paths tab which will provide information regarding the location of the identified licenses.
How to Identify the path of an Unknown License?- Click on the Unknown License.
- Follow this article which explains how to mark the license as vulnerable.
- Navigate back to the Xray tab of the Artifact.
- Click on the Security tab and click on the new marked vulnerability.
- Click on Impact Paths tab and then on the icon to view the path of the identified license.

These are the sources used to identify a license:
‘Local File’ - The licenses were found from one of the files included in the package.
‘JFrog’ - The license was matched against the JFrog Vulnerability Database.
‘Custom ’ - Custom license made by users (see How Xray Detects Package Licenses? For further information).